Beware of gift card fraud —don't let it hijack your perfect present

Kristine Solomon
·6 min read

Yahoo Life is committed to finding you the best products at the best prices. The products written about here are offered in affiliation with Verizon Media, Yahoo Life's parent company.

Gift cards are all too easy for scammers to get a hold of — and once they do, they can wreak havoc on your life. (Photo: Getty)
Gift cards are all too easy for scammers to get a hold of — and once they do, they can wreak havoc on your life. (Photo: Getty)

Gift cards can be a convenient compromise to give the perfect gift to that someone special. The only problem? Gift card fraud is a very real thing — and it’s woefully under-reported, say the experts at Tripwire.

“Generally speaking, gift card fraud is easier to commit than other types of scams,” cyber security expert Rafael Lourenco, Executive Vice President of fraud prevention group ClearSale tells Yahoo Life. “In fact, for many merchants, gift cards have the highest fraud attempt rates of all products sold.”

This is because gift cards are so easy to resell or convert into cash, he says, and gift card transactions are so hard to trace. For scammers, gift cards — which are not held to the same industry standards as credit cards — are a path of least resistance.

Gift card fraud Malwarebytes
Gift card fraud Malwarebytes

Once a scammer hijacks your gift card, they can drain its value effortlessly — but that’s just the beginning. Gift card fraud can be a gateway to even more complex cyber fraud. In the worst-case scenario, thieves can move on to stealing your payment details, draining your bank account and even stealing your identity.

And if they gain access to the username and password tied to a virtual gift card, fraudsters can also use it to access other accounts that use the same credentials.

LastPass Families can protect your family’s passwords from prying eyes

LastPass Families makes passwords impossible to crack. (Photo: LastPass)
LastPass Families makes passwords impossible to crack. (Photo: LastPass)

Experts say that maintaining unique passwords for each site you log into — and changing those passwords periodically — is a solid way to protect any kind of account, including a gift card or credit card account. Shockingly, 65 percent of people recently polled by cyber security site ID Agent said they use the same password across multiple sites — and 13 percent said they use the same password for everything.

If you’re secretly one of them — or you suspect members of your household are — LastPass Families will make it so that you’ll never have to remember multiple passwords again. LastPass Families is the industry’s leading password manager. It not only creates long and strong passwords for each account you log into, but it stores those passwords securely, syncs them across all your devices and automatically logs you in each and every time.

Get a 30-day free trial of LastPass Families, then it’s just $3.99 a month for a whole family’s worth of log-ins.

Behind the scenes, LastPass Families also resets your passwords periodically — so they’re constantly changing — a moving target for potential hackers with LastPass Families.

Unpacking gift card fraud: A glimpse into the mind of a real-life Grinch

“Fraudsters have creative ways of committing gift card fraud,” Lourenco tells Yahoo Life. But first, they need access to the gift card’s account number (and sometimes its PIN), which they can steal with a magnetic stripe reader or just by taking pictures of gift cards in the store before you even purchase them.

“Gift cards that are displayed and accessible to shoppers in stores are easy targets for fraudsters,” says Lourenco. “They can scratch off the PIN number protection and replace it with stickers sold online.”

E-gift card information can be stolen, “in a number of ways including phishing, SQL injection, social engineering, fraudulent employees or accidental disclosure,” adds Lourenco. “Hackers can also acquire gift card numbers in bulk from merchants, reward programs, etc. Once the cards are activated by a legitimate purchase, the fraudsters will transfer balances to another card or sell the card.”

Shop it: LastPass Families, free trial for 30 days then $4.99 a month, subscriptions.yahoo.com

Once they hack into the credit card used to purchase the gift card, scammers even make their way into your card’s loyalty program.

“Hackers will reroute miles and loyalty points to monetize the value in the credits into gift cards,” says Lourenco. And if hackers have access to the log-in credentials of an e-gift card or the credit card used to purchase it, both the gift card giver and the recipient becomes vulnerable to phishing scams, which can quickly infect your system with malware. All from a “harmless” and all-too-common present.

Examples of gift card fraud at major retailers

Gift card fraud LastPass Families
Gift card fraud LastPass Families

Shop it: LastPass Families, free trial for 30 days then $4.99 a month, subscriptions.yahoo.com

Scammers target physical gift cards as well as e-gift cards, especially those with auto-fill features. Starbucks’ virtual gift cards, for instance, which sync with the coffee chain’s app and automatically refill when tied to a bank account or credit card, have been at the center of fraud allegations in recent years.

Once scammers were able to hijack someone’s e-gift card — which was often loaded onto the Starbucks app — they went on to empty the card, then hack into the debit or credit card linked to the app. The crime was hard for authorities to trace, but Starbucks was quick to clarify in 2015 that it was not their company that was hacked — the customers themselves were.

Another high-profile gift card scam that happened this past spring involved tech giant Best Buy. Cyber criminals not associated with the company were sending bogus Best Buy gift cards to unassuming recipients along with a USB drive to activate the card, according to Komando. As soon as the USB was connected to the victim’s computer, it would barrage their system with malware.

gift card Malwarebytes
gift card Malwarebytes

Moral of the story: you never quite know the origin of your gift card or who might have scanned the code beforehand, ready to track its use as soon as it’s activated.

Having LastPass Families installed in your home computer could help prevent hackers from getting into your online accounts, wreaking havoc on your network and leaving you to pick up the pieces of a stolen identity. But, if you fall victim to the crime anyway this season, consider Lourenco’s advice: “If a consumer is victim of gift card fraud, they will need to contact their issuer for the chargeback so they can be reimbursed and the bank will likely have to cancel the compromised credit card and issue the consumer a new one,” he says.

Additionally, if anyone ever requests payment in the form of a gift card, it’s most definitely fraud and should be reported immediately to the Federal Trade Commission.

Shop it: LastPass Families, free trial for 30 days then $4.99 a month, subscriptions.yahoo.com

Read more from Yahoo Life:

Follow us on Instagram, Facebook, Twitter, and Pinterest for nonstop inspiration delivered fresh to your feed, every day

Want daily pop culture news delivered to your inbox? Sign up here for Yahoo Entertainment & Lifestyle's newsletter.